Skip to main content

VERJava

Replication of VERJava. VERJava is a two-stage approach for identifying vulnerable versions of Java Open Source Software (OSS) projects.

Install

pip install verjava

Usage

from verjava import verjava

# results will be a list of vulnerability repo tags
vul_tags: list[str] = verjava(
    repo_path="/path/to/your/repo",
    commit_id="your_commit_id", # Patch Commit
)

If you want to adjust the parameters, you can do so by passing them as keyword arguments:

vul_tags: list[str] = verjava(
    repo_path="/path/to/your/repo",
    commit_id="your_commit_id",
    tDel=1.0,  # Threshold for deleted lines similarity
    tAdd=0.9,  # Threshold for added lines similarity
    T=0.8,     # Threshold for vulnerability ratio
)

Metadata

Release files for verjava 0.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for verjava 0.0.3
File Size Uploaded
verjava-0.0.3.tar.gz 7.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for verjava 0.0.3
File Interpreter ABI Platform
verjava-0.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 15.8 kB

Release files / verjava-0.0.3.tar.gz

Download URL verjava-0.0.3.tar.gz
Size 7.7 kB
Tags Source
SHA-256 checksum
How to use checksums
ea3d0f433122a7264d8e2715252f7b4df30baa33cc1bb91661eeb9fe8b5b8474
BLAKE2b-256 checksum
How to use checksums
241a1a6381aa7bc22168c601d0384c88524138c65c4d5158a8a9d2662336f20d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 6, 2025.

Transparency log

Release files / verjava-0.0.3-py3-none-any.whl

Download URL verjava-0.0.3-py3-none-any.whl
Size 8.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c1d1eb078a690a137a257fc7141f60b787522ba758b4ad6566378906e9937922
BLAKE2b-256 checksum
How to use checksums
542d0e3cd9965690cefce7dbac672c168b33a002e9602fcf3ae7c1b562761bd9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 6, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.3 This release

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page